LogRhythm High Performance Appliances Data Sheet
LogRhythm High Performance Appliances Data Sheet
LogRhythm High Performance Appliances Data Sheet
High-Performance Appliances
LogRhythm high-performance appliances combine LogRhythm software with the
appropriate hardware elements to deliver maximum flexibility, with options ranging LogRhythm NextGen SIEM Platform
from convenient all-in-one platforms to high-performance, dedicated appliances
LogRhythm provides deep visibility into
for massive scalability in extremely large environments. LogRhythm’s distributed,
your environment, empowering you to
incrementally scalable architecture enables deployments to scale both horizontally
secure your networks and comply with
and vertically.
regulatory requirements.
Benefits include: LogRhythm delivers the following
• Building block architecture and geographic flexibility functionality on a unified platform:
• Expandable storage options with any sized model
• SIEM and log management on an
• Centralized management
Elasticsearch backend
• Flexible high availability and disaster recovery options
• Network forensics with application
LogRhythm XM ID and full packet capture
All-in-One (XM): LogRhythm XM appliances perform the work of a PM, DP, DX, and • Endpoint forensics and file integrity
AIE, all on a single appliance. Many deployments begin with an XM appliance and are monitoring (FIM)
expanded over time to include additional components to increase fault tolerance,
• Machine-automated security analytics
capacity and performance.
-- User and entity / network traffic /
LogRhythm Enterprise endpoint behavior analysis
Platform Manager (PM): LogRhythm PM appliances perform centralized event -- Statistical analysis, advanced
management and administration for a LogRhythm deployment, including alarming, correlation, and other techniques
case management and APIs, workflow automation and more. Each LogRhythm
• Unstructured and structured search
deployment has a single Platform Manager.
• Intuitive dashboards and visualizations
Data Processor (DP): LogRhythm DP appliances receive machine and forensic data
from Data Collectors and System Monitor agents and then perform distributed • Integrated case management
processing. DPs use our Machine Data Intelligence Fabric to transform data into a • SmartResponse™ automation platform
structured and contextualized form. Processors archive data and distribute both
original and structured copies to platform components that perform indexing,
machine-based security analytics, and alarming.
Data Indexer (DX): LogRhythm DX appliances perform distributed and highly scalable “ I t has been extremely easy
indexing of machine and forensic data. Multiple DXs can be clustered to improve for us to not only implement
performance and availability. Indexers store original raw data as well as structured LogRhythm, but also extend
data to enable structured and unstructured search-based analytics. LogRhythm to be a solution
for a number of other
Warm Node Data Indexer (DXW): The Warm Node appliance is an Elasticsearch
monitoring challenges.”
node with a closed index. It extends Time-to-Live (TTL) to over 365 days and is
a powerful and cost effective alternative to adding Data Indexers when seeking IT Professional, Large Retail Firm
additional storage.
AI Engine (AIE): LogRhythm AIE appliances deliver highly scalable, patented machine
analytics for advanced correlation and behavioral analysis, including automated
behavioral, histogram, statistical and whitelist profiling. AI Engine scales horizontally
to perform distributed analysis of massive workloads.
Disaster Recovery and High
Add-on Appliances Availability Options
Data Collector (DC): LogRhythm’s optional DC appliances collect log, flow, and
LogRhythm’s flexible Disaster Recovery and
machine data. They encrypt, compress and transport data from remote locations to
High Availability solutions can be tailored
LogRhythm DPs, either in real time or on a schedule.
to meet the specific requirements of your
NetMon (NM): LogRhythm NM appliances offer full visibility into network traffic, organization. LogRhythm appliances are built
identifying applications via deep packet inspection, and providing real-time with onboard redundancy for maximum fault-
unstructured search access to all metadata and packet captures. NetMon can also tolerance, and our active/active architectures
forward Layer 7 SmartFlow™ to the SIEM and third-party solutions for further analysis. maximize the return on your investment.
WWW.LOGRHYTHM.COM
Appliance Specifications
Max Processing Chassis Memory (Ex- Internal Storage Max Storage Height Width Length Weight
Model Series CPU Cores Ethernet Power
Rate Rack Units pandable) (Usable/Raw) (Usable/Raw) (in / cm) (in / cm) (in / cm) (lb / kg)
DC
DC3400 N/A 1U 4 16 (64) GB 278 GB/600 GB N/A Broadcom 5720 DP (2 x 1Gb) 100-240 VAC 1.68 / 4.28 18.99 / 48.24 26.65 / 67.69 30.42 / 13.8
Data Collector
WS
WS3400 N/A 1U 8 32 (384) GB 556 GB/1200 GB N/A Broadcom 5720 QP (4 x 1Gb) 100-240 VAC 1.68 / 4.28 18.98 / 48.24 27.57 / 70.05 40.96 / 18.6
Web Server